<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/">
  <channel about="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt">
    <title>gmane.linux.kernel.device-mapper.dm-crypt</title>
    <link>http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt</link>
    <description/>
    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>1</syn:updateFrequency>
    <syn:updateBase>1901-01-01T00:00+00:00</syn:updateBase>
    <items>
      <rdf:Seq>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/3001"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/3000"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2999"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2998"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2997"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2996"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2995"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2994"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2993"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2992"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2991"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2990"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2989"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2988"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2987"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2986"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2985"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2984"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2983"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2982"/>
      </rdf:Seq>
    </items>
    <image rdf:resource="http://gmane.org/img/gmane-25t.png"/>
    <textinput rdf:resource=""/>
  </channel>
  <image rdf:about="http://gmane.org/img/gmane-25t.png">
    <title>Gmane</title>
    <url>http://gmane.org/img/gmane-25t.png</url>
    <link>http://gmane.org</link>
  </image>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/3001">
    <title>Re: cryptosetup luks info resources</title>
    <link>http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/3001</link>
    <description>
Ah, yes. I thought of the bytes actually on disk. 

Arno
</description>
    <dc:creator>Arno Wagner</dc:creator>
    <dc:date>2008-12-01T21:53:41</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/3000">
    <title>Re: cryptosetup luks info resources</title>
    <link>http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/3000</link>
    <description>-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Arno Wagner schrieb:
ok here you are probably right. (too lazy to test now ;) )
if you thought of that from the beginning it was a little
missunderstanding on my side.
Jan
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFJNDHjBpRI6A8tC0MRAjVrAKC16QzcG/hQdBbsDoRyQUVEjVmFsQCfd8Y3
gSd58kMrHVlHCYdqIyEsRL8=
=o0kO
-----END PGP SIGNATURE-----


</description>
    <dc:creator>Jan Reusch</dc:creator>
    <dc:date>2008-12-01T18:50:11</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2999">
    <title>Re: cryptosetup luks info resources</title>
    <link>http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2999</link>
    <description>
The size is the same, but I think the space is not cleared bevore 
you actually create keys.

Arno
</description>
    <dc:creator>Arno Wagner</dc:creator>
    <dc:date>2008-12-01T18:33:49</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2998">
    <title>Re: cryptosetup luks info resources</title>
    <link>http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2998</link>
    <description>-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Arno Wagner schrieb:
hmmm i would say the size is always the same, it only depends on the
bitsize of the encryption key and doesn't change over time. (would be
bad if it does so ;) )


#root&lt; at &gt;wintermute:~# cryptsetup luksDump /dev/mapper/raid-jan
LUKS header information for /dev/mapper/raid-jan

Version:        1
Cipher name:    aes
Cipher mode:    cbc-essiv:sha256
Hash spec:      sha1
Payload offset: 1032
MK bits:        128
MK digest:      xx
MK salt:        xx
MK iterations:  10
UUID:           xx

Key Slot 0: DISABLED
Key Slot 1: ENABLED
        Iterations:             76720
        Salt:                   xx
        Key material offset:    136
        AF stripes:             4000
Key Slot 2: DISABLED
Key Slot 3: DISABLED
Key Slot 4: DISABLED
Key Slot 5: DISABLED
Key Slot 6: DISABLED
Key Slot 7: DISABLED

#root&lt; at &gt;wintermute:/tmp# dd if=/dev/mapper/raid-jan count=1032 of=test
#root&lt; at &gt;wintermute:/tmp# losetup -f test
#root&lt; at &gt;wintermute:/tmp# cryptsetup luksDump /dev/</description>
    <dc:creator>Jan Reusch</dc:creator>
    <dc:date>2008-12-01T18:30:13</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2997">
    <title>Re: cryptosetup luks info resources</title>
    <link>http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2997</link>
    <description>
Thanks -- looking forward to it!

Regards,

Sitaram

</description>
    <dc:creator>Sitaram Chamarty</dc:creator>
    <dc:date>2008-12-01T11:37:49</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2996">
    <title>Re: cryptosetup luks info resources</title>
    <link>http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2996</link>
    <description>
On Monday 2008-12-01 02:23, Jan Reusch wrote:

Quite big. But well, unless you really need multiple passwords,
you can also go with the normal dm-crypt encryption (without LUKS).

</description>
    <dc:creator>Jan Engelhardt</dc:creator>
    <dc:date>2008-12-01T10:57:14</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2995">
    <title>Re: cryptosetup luks info resources</title>
    <link>http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2995</link>
    <description>[...]

I am currently  looking through it. So far I like the 
introduction ;-)
Will send more feedback directly, not over this list.

Arno
</description>
    <dc:creator>Arno Wagner</dc:creator>
    <dc:date>2008-12-01T10:21:56</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2994">
    <title>Re: cryptosetup luks info resources</title>
    <link>http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2994</link>
    <description>
The LUKS keys span those 8MB or so at maximum. But only if you actually
have keys. Without them, there is only the ~600 Bytes header AFAIK.

Arno
</description>
    <dc:creator>Arno Wagner</dc:creator>
    <dc:date>2008-12-01T10:10:39</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2993">
    <title>Re: cryptosetup luks info resources</title>
    <link>http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2993</link>
    <description>...although I must also say I don't know why I said "8 MB".  There was
a recent thread right here where all this was hashed out, when someone
who lost the LUKS header was trying to recreate it.  Can't find it
now, but I seem to recall that thread said 8 MB.  Sorry for being so
vague...

Regards,

Sitaram

On Mon, Dec 1, 2008 at 9:35 AM, Sitaram Chamarty &lt;sitaramc-Re5JQEeQqe8AvxtiuMwx3w&lt; at &gt;public.gmane.org&gt; wrote:

</description>
    <dc:creator>Sitaram Chamarty</dc:creator>
    <dc:date>2008-12-01T09:08:47</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2992">
    <title>Re: cryptosetup luks info resources</title>
    <link>http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2992</link>
    <description>Hello,

On Mon, Dec 1, 2008 at 6:53 AM, Jan Reusch &lt;jreusch-Mmb7MZpHnFY&lt; at &gt;public.gmane.org&gt; wrote:

Look further down in that dump output for the phrase "AF Stripes".


see section 2.4 in http://luks.endorphin.org/LUKS-on-disk-format.pdf

Regards,

Sitaram

</description>
    <dc:creator>Sitaram Chamarty</dc:creator>
    <dc:date>2008-12-01T04:05:49</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2991">
    <title>Re: cryptosetup luks info resources</title>
    <link>http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2991</link>
    <description>-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

hi there

Sitaram Chamarty schrieb:
with 'cryptsetup luksDump device' you can see how much space your
luksheader needs.
most the time it is 1032 sectors (512 bytes a sector makes half a
megabyte) for me.
you can read this all in the initial paper [1] clemens wrote.
Jan

[1] http://clemens.endorphin.org/nmihde/nmihde-A4-os.pdf
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFJMzyrBpRI6A8tC0MRAl2bAJ420HpE9Cbs9IQXtqy4cPi1Gdz3TQCgqMlT
yrbFluk602iD67rFeusmpKA=
=1wiN
-----END PGP SIGNATURE-----


</description>
    <dc:creator>Jan Reusch</dc:creator>
    <dc:date>2008-12-01T01:23:56</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2990">
    <title>Re: cryptosetup luks info resources</title>
    <link>http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2990</link>
    <description>
Thanks!


most of the recent distros do now.  They'll throw up a password prompt
as soon as you insert a USB stick that's LUKS formatted, for
instance...

</description>
    <dc:creator>Sitaram Chamarty</dc:creator>
    <dc:date>2008-12-01T00:53:30</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2989">
    <title>Re: cryptosetup luks info resources</title>
    <link>http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2989</link>
    <description>
I thought the luks header spans about 4000 blocks (8MB or so) due to
the anti-forensic key splitting.

Perhaps it doesn't touch the first few blocks or so, and Marek's files
were well below that...

</description>
    <dc:creator>Sitaram Chamarty</dc:creator>
    <dc:date>2008-12-01T00:52:17</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2988">
    <title>luks partition missing</title>
    <link>http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2988</link>
    <description>Hello, I was using luks to encrypt a mdadm raid5 software raid array.
I recently had some trouble with the array, and luks is now reporting
that the partition is missing. the md0 device shows that there is a
partition on the device. Is it possible to recover this partition or
have i lost all my encrypted data? The array assembles ok, but i
cannot process the luksOpen command in cryptsetup. Thnx.

</description>
    <dc:creator>David Keymel</dc:creator>
    <dc:date>2008-11-30T19:30:55</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2987">
    <title>Re: cryptosetup luks info resources</title>
    <link>http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2987</link>
    <description>Thanks for info. It came out that hal didn't work for me because of some bugs 
in KDE.

Marek Aaron Sapota

On Sunday 30 November 2008 19:53:11 Jan Engelhardt wrote:
</description>
    <dc:creator>projects.gg.aaron-Re5JQEeQqe8AvxtiuMwx3w&lt; at &gt;public.gmane.org</dc:creator>
    <dc:date>2008-11-30T19:56:01</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2986">
    <title>Re: cryptosetup luks info resources</title>
    <link>http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2986</link>
    <description>
On Sunday 2008-11-30 19:22, projects.gg.aaron-Re5JQEeQqe8AvxtiuMwx3w&lt; at &gt;public.gmane.org wrote:


There is no reason to explicitly zero the device - it would take much too long.
It simply writes the LUKS header. Since ext3's header begins some 16-32KB
from the start of the device, nothing is lost unless you start making
a filesystem on the crypto device (/dev/mapper/...).


It already does recognize them as I gather from developers.

</description>
    <dc:creator>Jan Engelhardt</dc:creator>
    <dc:date>2008-11-30T18:53:11</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2985">
    <title>Re: cryptosetup luks info resources</title>
    <link>http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2985</link>
    <description>Trying to reproduce it I found what happened - I've made ext3 filesystem on file 
before I did cryptsetup luksFormat, but shouldn't it overwrite ext3 filesystem?

Your article was a quite a good read it indeed showed me some answers=)

One more question - can hal be made to recognize luks and automount such 
devices?

Thanks
Marek Aaron Sapota

On Sunday 30 November 2008 18:24:04 Sitaram Chamarty wrote:
</description>
    <dc:creator>projects.gg.aaron-Re5JQEeQqe8AvxtiuMwx3w&lt; at &gt;public.gmane.org</dc:creator>
    <dc:date>2008-11-30T18:22:36</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2984">
    <title>Re: cryptosetup luks info resources</title>
    <link>http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2984</link>
    <description>
This sounds weird; could you post the sequence of commands you used?


About a couple of months ago I wrote an entry level article on
encrypted file systems for a local magazine.  A PDF copy is at
http://sitaramc.googlepages.com/encrypted-file-systems.pdf -- I think
it should answer a lot of questions.

[If anyone else takes a look at it and has comments, please let me
know.  But remember the target audience for that article is people
who're just getting into this without using a GUI and all that --
"slow and steady" is important :-)

</description>
    <dc:creator>Sitaram Chamarty</dc:creator>
    <dc:date>2008-11-30T17:24:04</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2983">
    <title>cryptosetup luks info resources</title>
    <link>http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2983</link>
    <description>Hi,
I'm new to cryptosetup and luks. I've decided I'll try it out on a loop 
filesystem so I won't break anything and to my amazement I can properly mount 
encrypted file without luks and it appears empty (there was default ext3' 
lost+found directory), I can add files there and they don't appear when I mount 
it with luks. Like having two drives depending on mount method. This leads to 
my question - where can I find some resources about how luks works, for example 
why I can do the thing described above and what can break when I do it? Also 
most tutorials don't tell how to use some more advanced options (how to choose 
encryption algorithm and what is the default?) Could someone point me to a 
full featured tutorial?

Thanks in advance=)
Marek Aaron Sapota
</description>
    <dc:creator>projects.gg.aaron-Re5JQEeQqe8AvxtiuMwx3w&lt; at &gt;public.gmane.org</dc:creator>
    <dc:date>2008-11-30T12:59:20</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2982">
    <title>Re: encrypted home start-up problem with keyfile</title>
    <link>http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2982</link>
    <description>

wouldn't this crypttab entry ask for a password (third entry: `none')?

My problem is that I do want to have all partitions (/, /home, wap) 
encrypted and I do want to give the password only once during boot. So, 
at this point we would need the name of a key-file (containing the 
passphrase for /home and swap), which is accessible after the root 
partition is decrypted by the password given, without further asking me 
for passwords. My crypttab man page says that an entry `none' will ask 
for the password interactively.

The solution suggested by Heinz works excellently in my environment. Is 
there any argument AGAINST this solution - I mean, does this conflict 
with some other action during boot?

As a user (rather than an expert in encryption and boot process 
organization ...), I think that it would be nice to have a clear 
description how to proceed which is also mentioned in the openSUSE HOWTO 
pages.

Regards
Bernd


</description>
    <dc:creator>Bernd Speiser</dc:creator>
    <dc:date>2008-11-23T09:39:28</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2981">
    <title>Re: encrypted home start-up problem with keyfile</title>
    <link>http://permalink.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/2981</link>
    <description>
And not reproducible either.

# cat /etc/SuSE-release 
openSUSE 10.3 (X86-64)
VERSION = 10.3
# grep sda12 /etc/fstab /etc/crypttab 
/etc/fstab:/dev/mapper/sda12    /crypt               ext2       noauto 0 0
/etc/crypttab:sda12 /dev/sda12 none luks

works just fine.

cu
Ludwig

</description>
    <dc:creator>Ludwig Nussel</dc:creator>
    <dc:date>2008-11-21T10:34:41</dc:date>
  </item>
  <textinput about="http://search.gmane.org/?group=$group=gmane.linux.kernel.device-mapper.dm-crypt">
    <title>Search Engine</title>
    <description>Search the mailing list at Gmane</description>
    <name>query</name>
    <link>http://search.gmane.org/?group=$group=gmane.linux.kernel.device-mapper.dm-crypt</link>
  </textinput>
</rdf:RDF>
